Procurement

    Same WorkStream, Different Playbook: Vendor Onboarding Across Three Industries

    VeroTX Research
    VeroTX Research
    Procurement & Risk
    July 21, 202610 min read
    Share:
    Same WorkStream, Different Playbook: Vendor Onboarding Across Three Industries

    Vendor onboarding is the most deceptively uniform process in procurement. Every company does approximately this: collect vendor information, verify it, assess risk, negotiate terms, execute a contract, activate the vendor in the ERP.

    Six stages, universal. Which is why vendor onboarding software tends to ship as one workflow with a settings page.

    Then it meets an actual industry, and the settings page is not enough.

    The distinction that matters: WorkStream vs. Playbook

    Worth defining precisely, because the whole argument turns on it.

    • A WorkStream is the unit of work: "onboard a new vendor." It is the same everywhere.
    • A Playbook is the stage sequence inside that WorkStream: which stages run, in what order, with which agents, gates, and evidence requirements.

    Vendor onboarding is one WorkStream. It needs materially different Playbooks by industry, and the differences are not cosmetic. They change the sequence, the gates, and what counts as sufficient evidence to proceed.

    VeroTX's reference Procurement vendor onboarding Playbook runs eight stages with five agents, including a dedicated contract review agent handling large-context legal comparison against prior agreements. That is the baseline. What follows is what changes on top of it.

    Manufacturing: the qualification gate

    In manufacturing, the binding constraint is that a supplier's paperwork being correct tells you almost nothing about whether their parts are acceptable.

    What the Playbook has to add:

    • Physical qualification before commercial activation. First article inspection, sample approval, sometimes a site audit. A vendor can be fully contracted and still not approved to ship production parts.
    • Multi-tier visibility. The risk is frequently not in the direct supplier but two tiers back, in a sub-supplier the direct vendor may be reluctant to name.
    • Dual-sourcing as a default question. Onboarding one vendor for a critical component raises an immediate second question about who the backup is, and single-source approval is often itself a gated decision.
    • Long-cycle evidence. Qualification can take months. The Playbook has to hold a vendor in a partially-onboarded state without the WorkStream appearing stalled or being closed out.

    The sequence consequence: commercial and technical qualification run as parallel tracks with a joint gate, not as a linear sequence. A Playbook that treats contract execution as the final stage is wrong for manufacturing, because contract execution is not the point at which the vendor becomes usable.

    See Manufacturing and Hardware & Silicon.

    Healthcare: credentialing and the patient-data question

    Healthcare changes the risk model in two directions at once.

    • Credentialing rather than qualification. Licensure, accreditation, exclusion-list screening, and, critically, recurring re-verification. A license valid at onboarding expires. The Playbook cannot be a one-time run.
    • Data access as a first-class gate. Whether the vendor touches patient information changes the entire downstream path: business associate agreements, security assessment, access scoping. This single attribute forks the Playbook early.
    • Clinical stakeholders in the approval chain. Procurement does not unilaterally approve a clinical vendor. The Playbook has to route to clinical review and hold there, which means the escalation path includes people who do not live in procurement software.
    • Exclusion screening as an ongoing obligation. Checking a federal exclusion list once at onboarding does not satisfy the requirement.

    That last point has a specific, citable basis. HHS OIG maintains the List of Excluded Individuals and Entities and updates it monthly. Its 2013 revised Special Advisory Bulletin advises providers to check the list before employing or contracting with a person, and to check it periodically afterward to determine the exclusion status of current employees and contractors. Separately, federal Medicaid regulation at 42 CFR 455.436(c)(2) requires database checks of the LEIE and SAM no less frequently than monthly.

    The sequence consequence: the Playbook needs a recurring re-verification loop, not just a linear onboarding path. A monthly obligation cannot be met by a process that runs once. Vendor onboarding in healthcare is a subscription, not a transaction.

    See Healthcare.

    Financial services: third-party risk as a supervised process

    In financial services, vendor onboarding is a regulated activity in its own right, and the regulator's interest is in your process, not only your outcome.

    The governing document for US banking organizations is the Interagency Guidance on Third-Party Relationships: Risk Management, issued jointly by the Federal Reserve, FDIC, and OCC and final as of June 6, 2023. It replaced each agency's prior separate guidance. Two features of it map directly onto Playbook design:

    • It structures third-party risk management as a life cycle: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. That is a stage sequence, which is precisely what a Playbook encodes.
    • It states explicitly that not all third-party relationships present the same level of risk or criticality, and that sound practice accounts for the level of risk, complexity, and size of the institution along with the nature of the relationship. That is the regulatory basis for tiering.
    • Criticality tiering drives everything. A vendor's designated tier determines diligence depth, approval level, contract clauses, and ongoing monitoring cadence. Tiering is the first substantive decision, and it is a decision that has to be defensible.
    • Diligence depth scales with tier. Financial condition, business continuity testing, concentration risk, subcontractor disclosure. Not uniform across vendors, and not optional for critical ones.
    • Contractual requirements are mandated, not negotiated. Audit rights, exit provisions, and continuity obligations must be present. Their absence is a finding.
    • The examination requirement. The process itself gets examined. "We onboarded this vendor appropriately" needs to be demonstrable after the fact, in detail, potentially years later.

    The sequence consequence: the Playbook needs a tiering stage before diligence begins, with the depth of every subsequent stage derived from that tier. And it needs an audit trail built for external examination rather than internal reassurance.

    This is where Playbook version binding earns its place. Every action recorded in the Execution Ledger is bound to the Playbook version that was active at runtime, so the question "what was our vendor onboarding process in Q2 of last year, and did this vendor go through it" has a queryable answer rather than a reconstructive one.

    See Financial Services.

    Side by side

    ManufacturingHealthcareFinancial Services
    Gating questionCan they make it to specAre they credentialed and currentWhat tier of risk are they
    Primary evidenceSample approval, site auditLicensure, exclusion screeningFinancial condition, continuity testing
    ShapeParallel tracks, joint gateLinear plus recurring loopTier first, depth derived
    Approval chainQuality and engineeringClinical reviewRisk committee by tier
    Recurring obligationPeriodic requalificationContinuous re-verificationTier-based monitoring cadence
    Audit audienceInternal and customerAccreditorExternal examiner

    Three genuinely different processes. One WorkStream.

    Why this is a configuration problem, not a product-variant problem

    The instinct in enterprise software is to ship industry editions. It fails for a specific reason: real companies are not one industry.

    A medical device manufacturer needs manufacturing qualification and healthcare credentialing. A bank's data center vendors need financial services tiering and manufacturing-style qualification for hardware. An industry edition forces a choice that the business does not actually face.

    The alternative is a single WorkStream with configurable Playbooks, where:

    • Stage sequence, gates, and evidence requirements are configuration rather than code
    • Playbooks are versioned, so process changes are auditable events
    • A company running in two industries runs two Playbooks against one WorkStream definition

    What does not change across industries

    The uniform parts are worth naming, because they are where most of the automation value sits regardless of vertical:

    • Collecting and normalizing vendor-submitted information
    • Detecting duplicates against the existing vendor master
    • Comparing proposed contract terms against prior agreements and standard positions
    • Sequencing approvals and chasing the people who owe a decision
    • Recording what happened

    That last one is invariant and underrated. Every industry above has an audit audience. They differ in who is asking and how much detail they want, not in whether the question gets asked.

    What this does not solve

    • A bad vendor master stays bad. Duplicate detection helps at the point of entry. It does not retroactively clean twenty years of accumulated records.
    • Qualification cannot be compressed past physics. A Playbook can remove waiting that is purely administrative. It cannot shorten a sample approval that takes six weeks because the testing takes six weeks.
    • Playbooks need owners. A Playbook encoding last year's regulatory position is worse than no Playbook, because people trust it.
    • Tiering and criticality decisions stay human. Whether a vendor is critical is a judgment with consequences. Agents can gather the inputs and recommend. In regulated contexts, a person signs.

    FAQ

    Is vendor onboarding the same across industries? The stages look similar and the requirements are materially different. Manufacturing gates on physical qualification, healthcare on credentialing with recurring re-verification, and financial services on criticality tiering with examinable process evidence.

    What is the difference between a WorkStream and a Playbook? A WorkStream is the unit of work, such as onboarding a vendor. A Playbook is the stage sequence inside it: which stages run, in what order, with which gates and evidence requirements. One WorkStream can have many Playbooks.

    Why does vendor onboarding in healthcare need to repeat? Credentials expire and exclusion screening is an ongoing obligation. HHS OIG updates its exclusion list monthly and advises periodic re-checks of current contractors, and 42 CFR 455.436(c)(2) requires database checks no less frequently than monthly. A Playbook that runs once cannot satisfy a monthly obligation.

    What makes financial services vendor onboarding different? The 2023 Interagency Guidance on Third-Party Relationships from the Federal Reserve, FDIC, and OCC frames third-party risk management as a five-stage life cycle and states that relationships differ in risk and criticality. That makes tiering the first substantive decision, with the depth of every later stage derived from it, and it makes the process itself subject to examination.

    Do companies need a different system for each industry? No, and industry-specific editions actively create problems for companies operating across more than one, such as medical device manufacturers. A single WorkStream definition with configurable, versioned Playbooks handles the variation without forking the product.

    Sources

    Share:

    See How Procurement Eliminates Procurement Margin Leakage

    Explore our execution layer for Procure-to-Pay, from intake to payment, every handoff is automated.

    Explore Procurement Automation